Site protection and malware scans
Each site’s firewall rules and rate limits, the requests they blocked, and its malware scans: findings, Reinstall original and quarantine. See docs/security.md.
Reading needs Read only and changes need Manage, unless an endpoint says otherwise. How to read this page.
GET /api/security/overview
Section titled “GET /api/security/overview”The default protection, every site on one row, and each server’s rules folder.
- Level: Read only
- Returns:
SecurityOverviewDto
POST /api/security/sync
Section titled “POST /api/security/sync”Put every server’s rules and blocked addresses in line now rather than within the minute.
- Level: Manage
- Returns:
SecurityOverviewDto
GET /api/security/scans
Section titled “GET /api/security/scans”Every site with its scan settings, last scan and open findings.
- Level: Read only
- Returns:
{items[], inFlight}
POST /api/security/scans
Section titled “POST /api/security/scans”Scan these sites now (or every site that is scanned) - one scan per site at a time.
- Level: Manage
- Input:
{slugs?: string[]} - Returns:
{queued: slug[], already: slug[]}
GET /api/sites/:slug/security
Section titled “GET /api/sites/:slug/security”A site’s protection: its own settings, what is in force and why, and the requests it blocked.
- Level: Read only
- Returns:
SiteSecurityDto
PUT /api/sites/:slug/security
Section titled “PUT /api/sites/:slug/security”Change a site’s own protection; each part left out stays as it is.
- Level: Manage
- Notes: Destructive
- Input:
{level?: "off"|"standard"|"strict"|null, overrides?, customRules?: [{id?, action: "block"|"allow", match: "all"|"any", conditions[], note?, enabled?}]} - Returns:
SiteSecurityDto
GET /api/sites/:slug/security/blocked
Section titled “GET /api/sites/:slug/security/blocked”The latest requests the site’s protection blocked, and 7 days of counts per rule.
- Level: Read only
- Input:
?limit=100&rule= - Returns:
{items: BlockedRequestDto[], counts7d}
GET /api/sites/:slug/security/scan
Section titled “GET /api/sites/:slug/security/scan”Scan settings, the last scan and the ones before it.
- Level: Read only
- Returns:
{scan: SiteScanDto, history: ScanDto[]}
POST /api/sites/:slug/security/scan
Section titled “POST /api/sites/:slug/security/scan”Scan the site now.
- Level: Manage
- Notes: Job
PUT /api/sites/:slug/security/scan/settings
Section titled “PUT /api/sites/:slug/security/scan/settings”The site’s own scan settings; null follows the fleet’s.
- Level: Manage
- Input:
{enabled?: boolean|null, onFinding?: "report"|"quarantine-confirmed"|"quarantine-all"|null} - Returns:
SiteScanDto
GET /api/sites/:slug/security/findings
Section titled “GET /api/sites/:slug/security/findings”What the scans found, the most serious first.
- Level: Read only
- Input:
?status=open|ignored|resolved|quarantined|all (default open) - Returns:
{items: FindingDto[], counts}
POST /api/sites/:slug/security/findings/:id/ignore
Section titled “POST /api/sites/:slug/security/findings/:id/ignore”Ignore a finding; it stays ignored until its file changes.
- Level: Manage
POST /api/sites/:slug/security/findings/:id/unignore
Section titled “POST /api/sites/:slug/security/findings/:id/unignore”Take an ignored finding back.
- Level: Manage
POST /api/sites/:slug/security/findings/:id/resolve
Section titled “POST /api/sites/:slug/security/findings/:id/resolve”Mark a finding dealt with; a scan reopens it if it comes back.
- Level: Manage
POST /api/sites/:slug/security/findings/:id/reinstall
Section titled “POST /api/sites/:slug/security/findings/:id/reinstall”Reinstall original: download WordPress or the plugin again at its version, then scan again.
- Level: Manage
- Notes: Job · Destructive
POST /api/sites/:slug/security/findings/:id/put-back
Section titled “POST /api/sites/:slug/security/findings/:id/put-back”Put back a changed WPL7 file (the site must be running), then scan again.
- Level: Manage
- Notes: Job · Destructive
POST /api/sites/:slug/security/findings/:id/quarantine
Section titled “POST /api/sites/:slug/security/findings/:id/quarantine”Move the finding’s file out of the site, into its quarantine.
- Level: Manage
- Notes: Destructive
- Returns:
QuarantineItemDto
GET /api/sites/:slug/security/quarantine
Section titled “GET /api/sites/:slug/security/quarantine”Files moved out of the site, kept, restored or deleted.
- Level: Read only
- Returns:
{items: QuarantineItemDto[]}
POST /api/sites/:slug/security/quarantine/:id/restore
Section titled “POST /api/sites/:slug/security/quarantine/:id/restore”Put a quarantined file back where it was; its findings become ignored.
- Level: Manage
- Notes: Destructive
- Returns:
QuarantineItemDto
DELETE /api/sites/:slug/security/quarantine/:id
Section titled “DELETE /api/sites/:slug/security/quarantine/:id”Delete a quarantined file for good.
- Level: Manage
- Notes: Destructive
- Returns:
QuarantineItemDto